Files
cfw-auth/TODO.md

3.1 KiB

TODO

Production Environment Variables

Cloudflare vars currently covers the non-secret values in wrangler.jsonc. Cloudflare Secrets are currently empty, so production still needs the following runtime values configured before deploy.

Required For Current Production Path

Variable How to get it Configure as
BETTER_AUTH_SECRET Generate a high-entropy production secret, for example openssl rand -base64 32. Cloudflare Secret
RESEND_API_KEY Create or retrieve an API key from the Resend dashboard. The current mail adapter only supports MAIL_PROVIDER=resend. Cloudflare Secret
CAPTCHA_SECRET_KEY Use the Cloudflare Turnstile Secret Key. The provided TURNSTILE_SECRET_KEY value should be stored under this variable name. Cloudflare Secret
GOOGLE_CLIENT_SECRET Open Google Auth Platform / OAuth client settings and copy the client secret for the configured GOOGLE_CLIENT_ID. Cloudflare Secret

Set with:

pnpm exec wrangler secret put BETTER_AUTH_SECRET
pnpm exec wrangler secret put RESEND_API_KEY
pnpm exec wrangler secret put CAPTCHA_SECRET_KEY
pnpm exec wrangler secret put GOOGLE_CLIENT_SECRET

Configure Only If Enabling The Feature

Variable When needed How to get it
GITHUB_CLIENT_ID Enable GitHub OAuth. Create a GitHub OAuth App.
GITHUB_CLIENT_SECRET Enable GitHub OAuth. Generate it in the GitHub OAuth App settings.
GENERIC_OAUTH_PROVIDER_ID Enable generic OIDC/OAuth. Choose a provider id such as auth0, zitadel, or another stable name.
GENERIC_OAUTH_DISCOVERY_URL Enable generic OIDC/OAuth. Get the provider's .well-known/openid-configuration URL.
GENERIC_OAUTH_CLIENT_ID Enable generic OIDC/OAuth. Get it from the provider application settings.
GENERIC_OAUTH_CLIENT_SECRET Enable generic OIDC/OAuth. Get it from the provider application settings.
PASSKEY_RP_ID Enable passkeys. Use the relying-party domain, for example cfw-auth.bowong.cc or bowong.cc.
PASSKEY_RP_NAME Enable passkeys. Pick the user-facing product name, for example MixVideo.
PASSKEY_ORIGIN Enable passkeys. Use the full origin, for example https://cfw-auth.bowong.cc.
ENABLE_JWT Enable Better Auth JWT plugin. Set to true. Leave unset to disable.
ENABLE_BEARER Enable Better Auth bearer plugin. Set to true. Leave unset to disable.
EXPO_SCHEME Accept Expo app origins. Read the scheme from the Expo app config.
SMS_PROVIDER Enable SMS. Current code supports webhook or twilio.
SMS_WEBHOOK_URL Use SMS_PROVIDER=webhook. Use the SMS provider webhook endpoint.
TWILIO_ACCOUNT_SID Use SMS_PROVIDER=twilio. Get it from the Twilio Console.
TWILIO_AUTH_TOKEN Use SMS_PROVIDER=twilio. Get it from the Twilio Console.
TWILIO_FROM Use SMS_PROVIDER=twilio. Use a Twilio verified or purchased sending number.

Needs Cleanup

Variable Action
OAUTH_PROVIDERS Current source code does not read this variable. Either define its semantics and implement usage, or remove it from Env.